Pdu session secondary and slice-specific authentication and authorization using l3 wtru-to-network relay
Abstract
A wireless transmit/receive unit (WTRU) may be configured to receive a key identifier. The key identifier may be associated with a second WTRU. Additionally, or alternatively, the key identifier may include a 5G ProSe remote user key (5GPRUK) identifier (ID). The WTRU may be configured as a WTRU-to-network relay for the second WTRU. The key identifier may be received during a key request procedure. The key request procedure may be performed by the WTRU on behalf of the second WTRU. The WTRU may be configured to send the key identifier to a network function. The key identifier may be sent to the network function to initiate a secondary authentication procedure. The WTRU may be configured to receive an authentication response message from the second WTRU. The WTRU may be configured to receive a response from the network function.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 - 15 . (canceled)
16 . A first wireless transmit/receive unit (WTRU) comprising:
a processor configured to:
receive a key identifier associated with a second WTRU, wherein the first WTRU is configured as a WTRU-to-network relay for the second WTRU, and wherein the key identifier is received during a key request procedure performed by the first WTRU on behalf of the second WTRU;
store the key identifier associated with the second WTRU;
send a remote WTRU report message to a network function to initiate a secondary authentication procedure on behalf of the second WTRU, wherein the remote WTRU report message comprises the key identifier;
receive an authentication message that comprises the key identifier;
send the authentication message to the second WTRU based on the authentication message comprising the key identifier;
receive an authentication response message from the second WTRU, the authentication response message comprising the key identifier; and
receive a response to the remote WTRU report message from the network function, the response comprising the key identifier and indicating a result of the secondary authentication procedure.
17 . The first WTRU of claim 16 , wherein the key identifier comprises a 5G ProSe remote user key (5GPRUK) identifier (ID).
18 . The first WTRU of claim 16 , wherein the response to the remote WTRU report message comprises a remote WTRU report response message.
19 . The first WTRU of claim 18 , wherein the processor is further configured to, based on the remote WTRU report response message, transmit an indication that the second WTRU is authorized to communicate via a link or to release the link.
20 . The first WTRU of claim 19 , wherein the link is a PC5 link.
21 . The first WTRU of claim 16 , wherein the network function is identified by an access and mobility function (AMF) or a session management function (SMF).
22 . The first WTRU of claim 21 , wherein the AMF transmits the key identifier to the SMF.
23 . The first WTRU of claim 16 , wherein data network (DN) information is retrieved from the second WTRU, and wherein the secondary authentication procedure is triggered based on a determination of one or more of DN being authorized, DN requiring secondary authentication, and a prior authentication.
24 . The first WTRU of claim 16 , wherein the processor is further configured to release a link with the second WTRU if the result of the secondary authentication procedure is not successful.
25 . A method performed by a first wireless transmit/receive unit (WTRU) comprising:
receiving a key identifier associated with a second WTRU, wherein the first WTRU is configured as a WTRU-to-network relay for the second WTRU, and wherein the key identifier is received during a key request procedure performed by the first WTRU on behalf of the second WTRU; storing the key identifier associated with the second WTRU; sending a remote WTRU report message to a network function to initiate a secondary authentication procedure on behalf of the second WTRU, wherein the remote WTRU report message comprises the key identifier; receiving an authentication message that comprises the key identifier; sending the authentication message to the second WTRU based on the authentication message comprising the key identifier; receiving an authentication response message from the second WTRU, the authentication response message comprising the key identifier; and receiving a response to the remote WTRU report message from the network function, the response comprising the key identifier and indicating a result of the secondary authentication procedure.
26 . The method of claim 25 , wherein the key identifier comprises a 5G ProSe remote user key (5GPRUK) identifier (ID).
27 . The method of claim 25 , wherein the response to the remote WTRU report message comprises a remote WTRU report response message.
28 . The method of claim 27 , further comprising, based on the remote WTRU report response message, either transmitting an indication that the second WTRU is authorized to communicate via a link or releasing the link.
29 . The method of claim 28 , wherein the link is a PC5 link.
30 . The method of claim 26 , wherein the network function is identified by an access and mobility function (AMF) or a session management function (SMF).
31 . The method of claim 30 , wherein the AMF transmits the key identifier to the SMF.
32 . The method of claim 26 , wherein data network (DN) information is retrieved from the second WTRU, and wherein the secondary authentication procedure is triggered based on a determination of one or more of DN being authorized, DN requiring secondary authentication, and a prior authentication.
33 . A method performed by a base station comprising:
receiving a remote WTRU report message from a first wireless transmit/receive unit (WTRU) a key identifier associated with a second WTRU, wherein the first WTRU is configured as a WTRU-to-network relay for the second WTRU, and wherein the key identifier is received during a key request procedure performed by the first WTRU on behalf of the second WTRU; wherein the key identifier is received to initiate a secondary authentication procedure on behalf of the second WTRU; sending a request message to a network function, the request message comprising the key identifier; receiving a response message from the network function, the response message comprising a second identifier associated with the second WTRU; and sending a response to the remote WTRU report message to the first WTRU, the response comprising the key identifier and indicating a result of the secondary authentication procedure.
34 . The method of claim 33 , wherein the key identifier comprises a 5G ProSe remote user key (5GPRUK) identifier (ID).
35 . The method of claim 33 , wherein the response to the remote WTRU report message comprises a remote WTRU report response message.Join the waitlist — get patent alerts
Track US2025220425A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.